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Abstract — This paper discusses the details of the inherently different timekeeping systems for two interplanetary mis- 
sions, the NEAR Shoemaker mission to orbit the near-Earth asteroid 433 Eros and the STEREO mission to study and 
characterize solar coronal mass ejections. It also reveals the surprising dichotomy between two major categories of 
spacecraft timekeeping systems with respect to the relationship between spacecraft clock resolution and accuracy. The 
paper is written in a tutorial style so that it can be easily used as a reference for designing or analyzing spacecraft time- 
keeping systems. 

Index terms — NEAR, NEAR Shoemaker, 433 Eros. Discovery Program, STEREO, Sun-Earth Connections Program. 
Spacecraft timekeeping. Spacecraft time maintenance, Spacecraft clock 


I. INTRODUCTION 

The Near Earth Asteroid Rendezvous (NEAR) spacecraft, designed, built, and managed by The Johns Hopkins 
University Applied Physics Laboratory (JHU/APL) under the sponsorship of the National Aeronautics and Space 
Administration (NASA), was launched on February 17, 1996, aboard a Delta 11-7925 rocket. It was inserted into 
orbit about the near-Earth asteroid 433 Eros on February 14, 2000, becoming the first spacecraft ever to orbit any 
small planetary body. Renamed NEAR Shoemaker in March 2000 in honor of the late planetary scientist Eugene 
M. Shoemaker, it was the first space vehicle in the NASA Discovery Program. The Solar Terrestrial Relations 
Observatory (STEREO) Mission, part of NASA’s Sun-Earth Connections Program, is presently in the early stages 
of mission planning at JHU/APL. STEREO will study and characterize solar coronal mass ejection (CME) distur- 
bances using two identical Sun-pointing spacecraft. 

In late February 1998, 1 was asked to lead the effort to automate a system to correlate time received from the 
NEAR spacecraft to Coordinated Universal Time (UTC). In mid- 1999 I was asked to lead the effort to define a 
suitable timekeeping system for the STEREO Mission. It quickly became apparent that the principles governing a 
timekeeping system for STEREO, given the constraints under which STEREO would have to be designed, would 
have to differ substantially from the principles on which the NEAR timekeeping system is based. The discussion 
here involves timekeeping as it relates to the spacecraft system clock, which is generally a component of the 
spacecraft Command and Data Handling (C&DH) system. Distribution of time to the instruments and throughout 
the spacecraft is outside the scope of this paper. 

The primary goal of spacecraft timekeeping is to establish knowledge of the time of an onboard reference event 
with respect to which the time of every other event on the spacecraft can be measured. The means of establishing 
such knowledge differs from spacecraft to spacecraft. Typically, that reference event is the reference edge of a 
pulse that defines the fundamental timing cycle of the spacecraft C&DH system. There are several major types of 
spacecraft timekeeping systems, distinguished by the method used to establish knowledge of the time of the refer- 
ence event. For reference, we establish the following spacecraft timekeeping categories: 

Category I includes timekeeping systems in which transmission of the downlink telemetry transfer frames is syn- 
chronized to the reference event of the spacecraft C&DH system and in which correlation of the C&DH spacecraft 
clock to a standard time system (such as UTC) requires ground support. The NEAR spacecraft timekeeping sys- 
tem is an example of this category, in which dow nlink telemetry frames are synchronized to the fundamental 
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C&DH 1-Hz or 1-s timing cycle, and correlation to a standard time system (Terrestrial Dynamical Time, TDT) 
equivalent to UTC is accomplished on the ground. 


Category 2 includes timekeeping systems in which transmission of the downlink telemetry transfer frames is not 
synchronized to the reference event of the C&DH and in which correlation of the C&DH clock to a standard time 
system requires ground support. The planned configuration of the STEREO timekeeping system is an example of 
this category, in which downlink telemetry frames are not synchronized to the fundamental C&DH timing cycle, 
and correlation to a standard time system (UTC in this case) requires ground support. 

Category 3 includes all other varieties of spacecraft timekeeping systems. An example is the timekeeping system 
used in the JHU/APL-designed and built Thermosphere-Ionosphere-Mesosphere Energetics and Dynamics 
(TIMED) satellite, in which time (Global Positioning System [GPS] time) equivalent to UTC is normally provided 
to the C&DH directly from signals received from GPS satellites. 

This categorization reveals an interesting dichotomy in the relationship between spacecraft clock resolution and 
timekeeping system accuracy. The clock resolution and timekeeping accuracy for a Category 1 system are totally 
independent of each other. For a Category 2 system, on the other hand, timekeeping system accuracy is limited by 
the spacecraft clock resolution. For example, the Category 1 NEAR system meets an accuracy requirement of 20 
ms with respect to UTC with a spacecraft clock resolution of I s. Contrary to this, the much looser system accu- 
racy requirement of 0.5 s for the Category 2 STEREO timekeeping system cannot be satisfied with a spacecraft 
clock resolution of 1 s. 

Category 1 and Category 2 timekeeping systems may be “open-loop,” in which the spacecraft clock is free-running 
and never corrected by ground control, or “closed-loop,” in which the spacecraft clock is controlled and corrected 
by uplinked commands. Table I lists a few space missions (all designed or in planning at JHU/APL) illustrative of 
these various classifications. 


Table 1 

Examples of spacecraft timekeeping systems 



Open-Loop 

Closed-Loop 

Category 1 

NEAR [1] 

MSX [2][3] 


(launched 1996) 

(launched 1996) 

Category' 2 

CONTOUR [4], MESSENGER [5] 

STEREO [6] 

4 : ,4 r t~ ■ 

(future) 

(future) 


Note: The Midcourse Space Experiment (MSX) is an Earth-orbiting satellite sponsored by the Ballistic Missile Defense 
Organization, The Comet Nucleus Tour (CONTOUR) and the Mercury Surface, Space Environment, Geochemistry and 
Ranging (MESSENGER) mission are, like NEAR, interplanetary missions in NASA's Discovery Program. 


Once the Category 1 or Category 2 nature of a timekeeping system is recognized and accounted for, the general 
formalism introduced in this paper can be used to analyze either type. Whether the system is open-loop or closed- 
loop then becomes the driving issue in design and analysis of the system, particularly with regard to determination 
of the system time accuracy. 

All the interplanetary spacecraft listed in Table I require onboard knowledge of Earth time in order to be able to 
point a communication antenna toward Earth. This is accomplished in the “open-loop” systems of Table 1 by add- 
ing a bias to the spacecraft clock. The bias is provided by uplinked commands as often as necessary to ensure the 
accuracy of onboard know ledge of Earth time satisfies mission requirements. In this sense, all the “open-loop” 
systems listed have a “closed-loop” component that is important to understand for analysis of the accuracy of the 
onboard knowledge of Earth time. 
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11. GENERAL OVERVIEW OF TIMEKEEPING 


The primary goal of spacecraft timekeeping, as noted earlier, is to establish accurate knowledge relative to a stan- 
dard time system such as UTC of the time of an onboard reference to which all spacecraft events can be referred. 
Establishing this goal has the following purposes: 

• Time is needed by the spacecraft itself so that “time-tagged” commands uplinked from the ground, which 
must be executed at specific times, can be properly serviced. The spacecraft C&DH system may also sched- 
ule actions to be taken at specific absolute times. 

• Time is needed by the spacecraft instruments and other sources of downlink telemetry data so that information 
about internal or external events can be properly timeAagged for later correlation with other instruments (on 
the same or different spacecraft) or with other external events. 

A. Standard Time Systems 

Each spacecraft discussed in this paper (NEAR Shoemaker, STEREO, TIMED) establishes time of the reference 
event with respect to a different time system. A great many scales or systems for defining time intervals have been 
invented over the centuries. Many are based on the motions of the planets and the moon or the rotation of the 
Earth. These include the several “Universal Time ' systems UTO, UT1 and UT2; the now-redefined Ephemeris 
Time (ET) and Greenwich Mean Time (GMT) systems; and other lesser-known systems. (According to [7], UT1 
and GMT were identical before GMT was redefined.) In the latter half of the 20th century, new timescales were 
defined based on the Systeme International (SI) second (s), a time interval determined by a collection of atomic 
frequency standards that represents time at mean sea level [7,8], These “atomic times” include TAI (International 
Atomic Time), UTC (Coordinated Universal Time) and TDT or TT (Terrestrial Dynamical Time). The simple 
relationships between these time systems are 

TDT = TAI + 32. 184 s, 0) 

UTC = TAI - (number of leap seconds). (2) 

In addition, TDB (Barycentric Dynamical Time) is an important system commonly used in astronomy and equals 
TDT except for relativistic corrections [9], According to [9], Ephemeris Time (ET) was replaced by TDT in 1984. 
As currently used, however, ET may refer to either TDT or to TDB (see [10], for example). 


Another important and commonly used “atomic time” is GPS time, which is related to UTC as 

GPS time = UTC + (leap seconds since January 1980). (3) 

On January 1, 2000, GPS time = UTC + 13 s. 

In current usage, UTC and GMT are identical; this is the time system used for everyday timekeeping by most of 
the world’s population. It is the only time system considered here that involves leap second corrections; leap sec- 
onds are inserted to keep the difference AUT = UT1 - UTC to within 0.9 s [1 1][12][13]. The acronym UT is often 
used to refer to UTC but still sometimes refers to UT1 [12] and, because of that ambiguity, I have avoided using 
that acronym. The estimate of UTC provided by the United States Naval Observatory s (USNO s) Master Clock 
[8] is the UTC value generally used for U.S. space missions. We refer to that value as UTC(USNO) or, simply, 
UTC. 
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Fig. 1. Example of spacecraft clock based on 1-s C&DH cycle 


B. Knowledge oj the Time of the Reference Event 

For the NEAR Shoemaker, STEREO, and TIMED spacecraft, the reference event to which the time of every other 
event is measured is the reference edge of a 1 -pulse-per-second (1-PPS) signal that defines the beginning of the 
fundamental timing cycle of the C&DH system. 

Figure 1 is an example of a spacecraft clock based on a 1-PPS reference edge, in which knowledge of the time of 
the reference edge with respect to UTC is desired. The 1-PPS signal defines a 1-s C&DH cycle (or "tick”) that 
includes incrementing of the spacecraft clock once per second. The spacecraft clock provides an estimate of the 
time of the C&DH reference edge. In the special case in which the spacecraft clock is itself expressed in terms of 
UTC, such as the clock on STEREO, the clock value is an approximation to the true UTC of the C&DH reference 
edge. More generally, the clock is expressed in terms of some other timescale; commonly, the clock is a simple 
binary counter of the number of seconds since launch or since the clock was reset. 

TIMED is an example of an Earth-orbiting satellite that uses the GPS’s Earth-orbiting satellites to estimate the 
GPS time of the C&DH reference edge. This Category 3 timekeeping system does not depend on Earth-based 
estimates of spacecraft time derived from downlink telemetry. However, Category 1 and 2 timekeeping systems 
like those used on NEAR and STEREO and other interplanetary missions do depend on Earth-based estimates 
derived from downlink telemetry. For these systems, each downlink telemetry frame contains the value of the 
spacecraft clock corresponding to a specific C&DH reference edge which occurred at a particular value of 
UTC(USNO). Depending on the downlink data rates involved, multiple telemetry frames can include the same 
clock value referencing the same C&DH reference edge. On Earth, the time of the C&DH reference edge is not 
known but is estimated as ~ 


UTCperceived ~ UTC'grt - OWLT - TD SC - TF offset , where (4) 

L'TCperceived = the estimate on Earth of UTC corresponding to the C&DH reference edge; 

UTCgrt = the ground received time (GRT) in terms of UTC, which the receiving NASA Deep Space Net- 
work (DSN) station appends to the received telemetry transfer frame [14]; 

OWLT = one-way light time; that is, the signal transit time from the spacecraft to Earth; 

TDsc = encoding and transmission delay of a the first bit of a downlink telemetry- frame through the space- 
craft; and 

TFoffset = the offset from the C&DH reference edge to the beginning of encoding and transmission of the 
first bit of a downlink telemetry frame. 
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For a Category 1 timekeeping system, TFoffset is a known value (other than some small and generally negligible 
jitter), and the uncertainty in TFoffset is essentially zero. This is because the time of transmission of each 
downlink telemetry frame is synchronized to the C&DH reference edge. If the uncertainties in UTC grt , OWLT, 
and TDsc can be kept small, then the uncertainty Co in UTCperceived can be kept small, regardless of the resolu- 
tion of the spacecraft clock. 

For a Category 2 timekeeping system, the time of transmission of each downlink telemetry frame is not synchro- 
nized to the C&DH reference edge, and the uncertainty in TFoffset depends on the resolution of the clock. Sup- 
pose the spacecraft clock resolution is 1 s and each telemetry frame contains the clock value corresponding to a 
C&DH reference edge. That allows us on the ground to determine the time of transmission of the first bit of the 
telemetry frame to within the 1-s window defined by the spacecraft clock. We could choose TFoffset to be any 
value within a 1-s w indow. It’s likely we w ould choose it to be at the center of that window to minimize the 
maximum error in TFoffset* so the uncertainty in TFoffset would be > 0.5 s. That, in turn, means the uncertainty 
in the estimate UTCperceived of UTC w'ould be Uq > TFoffset ^ 0.5 s. 

U 0 is an important figure of merit for Category 1 and Category 2 systems and an important tool for designing 
spacecraft timekeeping systems. Some examples illustrate this point. 

For the NEAR Shoemaker Category 1 timekeeping system, the uncertainty in TD S c* the transmission delay of a 
telemetry frame through the spacecraft, varies as a function of downlink telemetry data rate. By using only te- 
lemetry downlinked at the highest four data rates, we have kept U 0 <2 ms. This, in turn, allows the NEAR time- 
keeping system to meet mission requirements. 

The Category 2 timekeeping system originally proposed for STEREO is based on a 1-s clock resolution and results 
in U {) > TFoffset > 0.5 s. This means the estimate of UTC PERC eived of the UTC of the C&DH reference edge could 
be in error by as much as 0.5 s, which will not satisfy the mission requirements described below. In order to sat- 
isfy mission requirements in this case, it is necessary to somehow' reduce TFoffset* The method now planned for 
STEREO involves addition of a subsecond “vernier" counter on the RF downlink card, properly synchronized to 
the 1-PPS signal which defines the C&DH reference edge and inserted together with the spacecraft clock value 
into each downlink telemetry frame. This results in an uncertainty in TFoffset of less than 2 ms and allows us to 
achieve a U () value of better than 30 ms, which will allow' mission requirements to be met. 

The backup timekeeping system for the Earth-orbiting TIMED satellite, to be used if the primary GPS system 
fails, is also a Category 2 system with Uq > TFoffset — 0*5 s. The method planned for establishing UTCperceived 
relies on an interesting but complex ground system technique that depends on the availability of high-data-rate 
downlink telemetry. At the highest downlink rate, the interval between the first bit of two consecutive frames is 
only a few milliseconds. Many frames containing the same spacecraft clock value are downlinked per second. 

The ground system monitors the spacecraft clock value provided in each telemetry frame until it observes a change 
in that value due to the C&DH 1-PPS reference edge. Since the time between the first bit of consecutive frames is 
only a few' milliseconds, the effective uncertainty in the value of TFoffset for the first frame downlinked after the 
clock has incremented can be reduced to a few r milliseconds, and the value of Uq reduced correspondingly. 

To recapitulate, the following categories relevant to establishing knowledge of the time of the reference event have 
been identified in this paper: 

Category ; 1: Knowledge of the time of the C&DH reference edge depends on downlink telemetry synchronized to 
that reference edge. 

Category 2: Knowledge of the time of the C&DH reference edge depends on downlink telemetry that is not syn- 
chronized to that reference edge. 

Method 1: Unaided (e.g., original STEREO proposal) 

Method 2: Vernier-aided (e.g., revised STEREO approach) 

Method 3: Ground resynchronization-aided (e.g., TIMED backup mode) 

Category ? 3: All other systems (e.g., TIMED GPS mode) 
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C Timekeeping System Figures of Merit 


The figure of merit U 0 was introduced in the previous section. This value is a measure of the observability of the 
spacecraft clock relative to a standard time system. Several other figures of merit (commonly called FOMs in the 
engineering community) also are important for spacecraft timekeeping systems. 

Reference [15] provides the definition “ Accuracy : the degree of conformity of a measured and/or calculated value 
to some specified value or definition. " In this paper we discuss the end-to-end system accuracy S 0 and the space- 
craft clock accuracy or "extended clock" accuracy A 0 < 5 0? each with respect to a specified standard time system. 

It should be clear that we must have U {) <A 0 < S {) for any Category 1 or Category 2 system. 

Controllability of the spacecraft clock is an issue for closed-loop timekeeping systems. In this paper, we describe 
this FOM as the maximum allowable interval A/ CL between clock corrections. It will be seen that Af cl is a func- 
tion of To, A iU spacecraft clock drift, and the short-term predictability of spacecraft clock drift. 


III. THE NEAR TIMEKEEPING SYSTEM 

The NEAR Mission came to an end in February 2001 with the successful landing of the spacecraft on 433 Eros. 
During the mission, the NEAR Mission Operations Center at JHU/APL was the primary source of information 
about system time maintained onboard the NEAR spacecraft. It had the responsibility of correlating that system 
time with UTC [16]. The algorithm described here for computing that correlation was fully implemented and 
automated and was in daily use at the NEAR Mission Operations Center. 

A. The NEAR System Clock (MET) 

The NEAR Shoemaker spacecraft maintains an onboard clock called the Mission Elapsed Time (MET). Correla- 
tion of MET with UTC requires an understanding of the delays and of the uncertainties in the delays to which 
NEAR telemetry is subject. 

The NEAR C&DH system contains redundant Command and Telemetry Processors (C/TP), called C/TP 1 and 
C/TP 2. Throughout the mission, C/TP 1 has been the active, or primary, C/TP responsible for control of teleme- 
try generation, the onboard data recorders, and the C&DH 1553B data bus. 

In the telemetry, the primary C TP is generally designated the BC (for 1553B bus controller), and the secondary or 
backup C/TP is designated RT (for 1553B remote terminal). The BC and RT C/TPs each maintain a 32-bit un- 
signed integer software counter called MET, with resolution of one count per second. In addition, several other 
MET counters are maintained in other subsystems of the spacecraft. The MET that concerns us here is that main- 
tained by the primary (i.e., BC) C/TP. This MET is sometimes called the "system MET” or "spacecraft clock" to 
distinguish it from the other MET counters maintained on the spacecraft. 

In addition, each NEAR telemetry frame can contain numerous entries for the various MET counters, including 
even more than one entry for the system MET. The primary C/TP increments its MET counter at a fixed latency 
relative to the reference edge of a 1-PPS signal generated by a hardware divide chain driven by a crystal oscillator. 
The interval between successive 1-PPS reference edges is called a time tick. Each time tick corresponds to a dif- 
ferent value of system MET. Tick a* is the time tick in which the NEAR telemetry "transfer frame" is built or as- 
sembled. The corresponding system MET value (which is placed in the transfer frame secondary header [17]) is 
the value that appears most suitable for determining the correlation between MET and UTC. Actual transmission 
of the NEAR telemetry transfer frame to Earth occurs in the next tick, which is called tick a + 1 here. 

NEAR telemetry is stored at the Mission Operations Center in an Oracle database called the Assessment Database. 
It is of interest that the Assessment Database contains more than 100 distinct names referring to entries for the 


6 



various MET counters. Identifying the one name that properly references the “system MET” counter at the appro- 
priate time tick was critical in implementation of the algorithm discussed here. 

The 1-PPS reference edges define the fundamental NEAR C&DH timing cycle of 1 Hz or 1 s. Downlink teleme- 
try transfer frame transmissions are synchronized to the C&DH 1-Hz timing cycle. We therefore call the NEAR 
timekeeping system a Category 1 system as defined in the Introduction. This classification is reflected in the algo- 
rithm used for correlation to UTC. 


B. Correlating MET to UTC 

Given the MET corresponding to tick x, the corresponding UTC, ignoring leap seconds, is perceived on Earth as 
having the value UTC PE rceived defined by equation (4), rewritten here in a slightly different form reflecting com- 
mon usage: 

UTCperceived = UTCgrt - OWLT - A sc - REFi PPS , 

where 

UTCperceived is the estimate on Earth of UTC corresponding to the C&DH reference edge; 

OWLT is the one-way light time, or the time it takes an electromagnetic wave (light or radio frequency 
emissions) to travel in free space from the NEAR antenna to the DSN station on Earth, 

A sc is the time interval between the C&DH reference edge just prior to the transmission of a downlink te- 
lemetry frame and the radiation ot the first bit ot that frame from the NEAR antenna, and 
REFipps is the “time reference offset”. 


Software employing the SPICE 1 system is used at the NEAR Mission Operations Center to compute OWLT, given 
the DSN ground received time UTC grt , the location of the receiving DSN station, and the spacecraft and Earth 
ephemerides. 

The parameter Asc in these calculations is the time delay between the 1-PPS reference (leading) edge tor tick x + 1 
and the radiation of the first bit of the telemetry transfer frame from a NEAR antenna. (The exact antenna used and 
the exact path through the NEAR telecommunications system do vary [18].) 

Table II gives values for A sc for various telemetry data rates and convolutional encoding rates. The table does not 
include possible delays of less than 2 or 3 ps through the telecommunications downlink hardware; such delays are 
negligible compared with the known delays and uncertainties. 

Table II provides values of spacecraft delay with respect to the 1-PPS reference edge for tick x + 1 (Fig. 1), but 
the MET value available in the transfer frame secondary header is defined with respect to the 1-PPS reference 
edge for tick x. The parameter REFipps in equation (5) accounts for that difference in reference edges and always 
has the value +1 s. This is sometimes called the system MET “buffering delay.” With that definition, the quantity 
(OWLT + A S c + REFipps) is the total time delay from the 1-PPS reference edge that begins the time tick during 
which a NEAR telemetry transfer frame is assembled until receipt of the first transfer frame bit at a DSN ground 
station. Also, A sc + REF 1PPS = TD SC + TFqffset is the delay from that l-PPS reference edge to radiation of the 
first bit of the transfer frame from the NEAR antenna. 


1 The Navigation and Ancillary Information Facility (NAIF) of NASA’s Jet Propulsion Laboratory (JPL) has developed and maintains an ex- 
tensive collection of software tools called SPICE (an acronym taken from “Spacecraft Planet Instrument C-matnx Events ) SPICE data tiles, 
called kernels, provide parameters important for calculations relevant to space missions and include, for example, NEAR cphemeris and LIE 
leap seconds. The NEAR Mission Operations Center generates a SPICE spacecraft clock kernel (SCLK kernel) to define known relationships 
between NEAR MET and TDT. All computations internal to SPICE utilize TDB. However, SPICE includes a variety ot tools that readily 
convert between TDB and other time systems. 
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Table II 

Total spacecraft delay, Aso for various telemetry data rates and convolutional encoding rates. Possible delays of less than 2 or 
3 P s through the telecommunications downlink hardware are not included; such delays are negligible compared with the 
known delays and uncertainties. 


Data Rate 

Mode 

Frames 
per sec- 
ond 

Average 
C&DH 
Delay, ms* 

Uncertainty 
C&DH 
1 Delay, ms 

in Reed-Solomon 
Encoded 
Rate, bps 

Convolutional 
Encoding 
Rate R 

TCU** 
Delay, ms 

Total Spacecraft 
Delay A S c, ms* 

26.496 kbps 

Normal 

3 

0.412 

±0.132 

30336.00 

R = 1/2 

0.0041 

0.4 ±0.13 







R= 1/6 

0.0014 

0.4 ±0.13 

17.664 kbps 

Normal 

2 

0.618 

±0.198 

20224.00 

R = 1/2 

0.0062 

0.6 ±0.20 







R = 1/6 

0.0021 

0.6 ±0.20 

8.832 kbps 

Normal 

1 

1.236 

±0.396 

10112.00 

R = 1/2 

0.0124 

1.2 ±0.40 







R= 1/6 

0.0041 

1.2 ±0.40 

4.416 kbps 

Normal 

1/2 

2.472 

±0.791 

5056.00 

R = 1/2 

0.0247 

2.5 ±0.79 







R = 1/6 

0.0082 

2.5 ±0.79 

2.944 kbps 

Normal 

1/3 

3.708 

±1.187 

3370.67 

R = 1/2 

0.0371 

3.7 ± 1.2 







R = 1/6 

0.0124 

3.7 ± 1.2 

1.104 kbps 

Normal 

1/8 

9.889 

±3.165 

1264.00 

R = 1/2 

0.0989 

10.0 ± 3.2 







R = 1/6 

0.0330 

9.9 ± 3.2 

39.4286 bps 

Emer- 

gency 

1/224 

276.898 

±88.607 

45.143 

R = 1/2 

2.7690 

279.7 ±88.6 







R = 1/6 

0.9230 

277.8 ±88.6 

9.8571 bps 

Emer- 

gency 

1/896 

1 107.590 

±354.429 

11.286 

R = 1/2 

11.0759 

11 18.7 ±354.4 







R= 1/6 

3.6920 

1 1 1 1.3 ± 354.4 


*For 26.496 kbps data rate, add 1/3-s delay for second transfer frame, 2/3-s delay for third transfer frame. 
For 17.664 kbps data rate, add 1/2-s delay for second transfer frame. 

**Telemctry Conditioning Unit. 


C. Using TDT for MET Correlation 

The use of UTC-based parameters in equation (5) ignores leap seconds. There are many alternatives to this form 
that involve conversion betw'een LTC and other time systems, incorporating leap seconds into the conversion in- 
stead of in evaluation of the equation itself. The algorithm provided to the NEAR Mission Operations Center for 
correlation of MET with UTC actually uses TDT. The relationship between TDT and UTC is 

TDT = UTC + 32. 1 84 s + n, (6) 

where n is the number of leap seconds. The equation for correlation of MET with UTC then becomes 

TDTp ERt hived = TDTgrt - OWLT - A S c - REF IPPS . (7) 
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Because of equation (6), we refer to both TDT PE rceived and UTC P erceivf.d as the “UTC estimator.” 

D. Uncertainty in the UTC Estimator 

Equation (7) shows that the uncertainty ti(UTCperceived) = U 0 in our knowledge of the TDT or UTC of the 1-PPS 
reference edge corresponding to values of MET is composed of the uncertainties rj(UTC GRT ) in TDTgrt, 
r|(OWLT) in OWLT, and V[(Asc) in A S o (The uncertainty in REFi PPS is not zero but is limited to the jitter in the 1- 
PPS signal, which is negligible for this application.) The uncertainty p(UTCgrt) is given by Reference [14] as 
bounded 2 by ±0.1 ms. Because of ephemeris uncertainties and relativistic effects that the SPICE software does not 
account for, we believe that SPICE computes OWLT with an uncertainty of±l ms, uniformly distributed. The 
uncertainty in A S c, taken from Table 11, is also uniformly distributed. That gives 


ti(UTCperceived) =/!n(UTC GRT ), q(OWLT), n(A S c)}, W 

which expresses = t|(UTC PE rce!ved) as some undefined function of the component uncertainties. UTC G rt and 
OWLT are correlated since SPICE computation of OWLT uses UTC G rt but Asc is independent of OWLT and 
UTC grt - Table 111 summarizes our knowledge of the uncertainties in the estimator TDT PE rceived or UTC PE rceived- 
Neither the root-sum-squares (RSS) summation nor the total summation of component uncertainties is a com- 
pletely satisfactory description of the uncertainty in the UTC estimator, but these values do provide rough esti- 
mates of that uncertainty. 


Table III 

Uncertainties in the NEAR UTC estimator 


Data Rate 

Ground Re- Spacecraft- Earth 

ceived Time Signal Transit time Total Spacecraft 

UTC G rt, ms OWLT, ms Delay A sc , ms 

RSS 

SUM 

26,496 kbps 

±0.1 

±1. 

±0.132 

±1.0 

±1.2 

17,664 kbps 

±0.1 

±1. 

±0.198 

±1.0 

±1.3 

8,832 kbps 

±0.1 

±1. 

±0.396 

±1.1 

±1.5 

4,416 kbps 

±0.1 

±1. 

±0.791 

±1.3 

±1.9 

2.944 kbps 

±0.1 

±1. 

±1.187 

±1.6 

±2.3 

1 . 1 04 kbps 

±0.1 

±1. 

±3.165 

±3.3 

±4.3 

39.4286 bps 

±0.1 

±1. 

±88.607 

±89 

±90 

9.8571 bps 

±0.1 

±1. 

±354.429 

±354 

±356 


David Tillman of JHU/APL, who did an outstanding job programming the Mission Operations Center component 
of the NEAR timekeeping system, has observed that the performance of the NEAR timekeeping system is very 
sensitive to the uncertainty rj(OWLT) in the spacecraft ephemeris. The Jet Propulsion Laboratory (JPL) provides 
to the NEAR Mission Operations Center at JHU/APL the SPICE ephemeris kernel for the NEAR spacecraft and 
provides improved versions of that kernel as the mission progresses. Different versions of the SPICE ephemeris 
kernel provide different estimations and predictions of spacecraft ephemeris, with differing levels of r|(OWLT) for 
any particular period of time; Mr. Tillman has worked out procedures to ensure that the Mission Operations Center 
uses only those available ephemeris kernels which are expected to provide the best estimates of ephemeris. 

E. Prediction of Future MET Drift 

Given MET and TDT PE rceived> we can create a plot showing the correlation between MET and TDT or UTC for 
all past values of MET. This is useful but is not all we want. We wish to be able to predict the value of the MET 
counter at any given future time defined by a value of UTC or TDT. 


: This is an upper bound on UTCgrt accuracy imposed by calibration limits of the DSN time-stamping system. 
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The method for making this prediction at the NEAR Mission Operations Center is simple: the predicted future rate 
of drift of the MET counter relative to TDT is assumed to be equal to its measured short-term rate of drift. Over 
periods of a few days to a few weeks, this method works surprisingly well for the required NEAR total system 
timing accuracy of ±20 ms. The MET clock drift has been observed to vary from about 16 to 38 ms per day rela- 
tive to TDT, but the change in drift is generally small from day to day. 

Note that since we are concerned with determining the relationship between spacecraft MET and Earth-based 
UTC, any relativistic effects on the spacecraft MET oscillator due to its environment may be viewed from the 
Earth as components of oscillator (MET) drift. Thus we need not explicitly compute the magnitude of those rela- 
tivistic effects. 

F. Dissemination and Accuracy of NEAR Time 

Time is known on the NEAR spacecraft only in terms of the system MET clock. The NEAR Mission Operations 
Center at JHU/APL disseminates time to the scientific community by means of a SPICE spacecraft clock (SCLK) 
kernel, which describes known and predicted relationships between NEAR MET and TDT. 

The SCLK kernel includes a table of time intervals, each specified as a time “coefficients triplet” consisting of 
MET at the beginning of the time interval, the corresponding TDT PERC eived computed from equation (7), and the 
predicted rate of change of TDT with respect to the MET counter during that interval [19]. Table IV illustrates a 
portion of the time coefficients triplet table of an SCLK kernel obtained from Reference [20]. It includes, as well, 
the equivalent rate of drift of the MET counter with respect to TDT or UTC. Note that the rate of change given in 
the SCLK kernel indicates that the spacecraft MET counter increments faster than once per TDT ( SI) second. 

Table IV 

Portion of a recent NEAR Shoemaker SCLK kernel with equivalent MET drift rates. 


— SCLK COEFFICIENTS TRIPLET 

MET Drift 

Rate 

(ms/day) 

Actual MET 

Earth Time 

Rate of Change 


(ms) 

(TDT) 

(TDT s/ MET ms) 


1.2301577300e±l 1 

@1 1 -JAN-2000- 15:46:52.289 

9.999996623 le-04 

29.2 

1.23782 14600e± 11 

@:20-J AN-2000-1 2:39:45.036 

9.9999966955e-04 

28.6 

1.2474293600e+ll 

@3 l-JAN-2000-1 5:32:54.713 

9.9999966406e-04 

29.0 

1. 2593273 100e+ 11 

@ 1 4-FEB-2000- 1 0:02:49.3 1 9 

9.9999966865e-04 

28.6 

1.2855638600e+l 1 

@ 1 5-MAR-2000- 1 8:50:23.455 

9.9999967057e-04 

28.5 

1. 30439 17100e+ 11 

@06-APR-2000- 13:50:07.829 

9.9999966756e-04 

28.7 

1.31 18129200e±l 1 

@ 1 5 - APR-2000-03 : 5 8 :48 . 5 77 

9.9999966077e-04 

29.3 

1.3285501400e±l 1 

@04-M AY-2000- 12:54:10.014 

9.9999966383e-04 

29.0 

1.3328877800e+l 1 

@09-MAY-2000- 13:23:33.874 

9.9999967655e-04 

27.9 

1.3414737700e±ll 

@ 1 9-MA Y-2000- 1 1 :53:32.59 1 

9.9999967025e-04 

28.5 

l .3458302500e+l 1 

@24-MAY-2000- 12:54:20.442 

9.9999965803e-04 

29.5 

1.3527066600e+l 1 

@01-JUN-2000- 11:55:01.201 

9.9999965024e-04 

30.2 


Notes: 

1) For the time period shown, TDT is larger than UTC by 64.184 s [12]. 

2) These data are taken from NEAR Shoemaker SCLK kernel “near_154.tsc,” dated June 1, 2000. 


Linear interpolation can be used between entries to estimate the correlation between TDT (or UTC) and MET. 
For times later than the last time coefficients triplet entry in the SCLK kernel, linear extrapolation is used to pre- 
dict future correlation between MET and TDT. Let MET 0 , rate 0 , and TDT 0 constitute the last entry in the SCLK 
kernel and let MET, = MET 0 x 10 3 represent MET in seconds; rate, = rate 0 x 10 3 ; and TDT, = TDT 0 . The pre- 
dicted relationship is 


10 



or 


TDT = TDT, + (rate,)(MET - MET,), 
MET = MET, + (TDT - TDT,)/rate„ 


( 9 ) 


( 10 ) 


As new telemetry is received from the spacecraft, the NEAR Mission Operations Center compares the predicted 
MET drift with the actual MET drift for selected downlinked telemetry frames, chosen using a complicated data- 
quality filter, and adds a new time coefficients triplet to the SCLK kernel whenever the difference between the 
predicted and actual values is too great. Given a new value MET„ of MET from telemetry and a new TDT W — 
TDTperceived computed from equation (7), the (perceived) error in the prediction of MET drift is £ D = predicted 
MET drift - observed MET drift = [(TDT„ - TDT/)/rale, - (TDT„ - TDT/)] - [(MET n - MET/) - (TDT„ - TDT/)], 
or 

E d = (TDT„ - TDT,)/rate, - (MET* - MET,), (11) 

and the perceived error in the prediction of TDT„ is 


£p = rate, x (MET, - MET,) - (TDT„ - TDT,) 

= - rate, x E D - — E D , since rate, - 1 . (12) 

The NEAR end-to-end system accuracy requirement is S 0 = 20 ms. This means the magnitude of the error in the 
estimate of TDT at the instruments as computed using the SCLK kernel must be less than S 0 . There exists an £max 
such that, so long as |£ P | < £ M ax , the system error requirement S 0 = 20 ms is satisfied. Whether or not that re- 
quirement is satisfied throughout the entire interval TDT„ - TDT, is unknown, since we do not generally have te- 
lemetry available for the entire interval. For convenience, we used £d as our test parameter, which is valid since 
|£ P | = rate, x |£ D | < |£ D | < £ MAX and since |£ D | - |£ P | is negligible. 

The NEAR system time error budget, excluding the prediction of MET drift relative to UTC or TDT, consists of 
these components: 

• DSN timing errors and range uncertainty = ±1.1 ms = ^(UTCgrt) + q(OWLT) 

• C/TP to transmitter time synchronization = see Table II = rj(A S c) 

• C/TP to Imager time synchronization = ±0.001 ms 

• Imager Shutter time control uncertainty = ±0. 1 ms 

• C/TP to Guidance & Control (G&C) synchronization = ±5 ms 

• G&C to attitude snapshot synchronization = ±2 ms 

Referring to Table II, we see that the C/TP to transmitter time synchronization varies from ±0.13 to ±354.4 ms, 
depending on telemetry data rate. How do we combine all these sources of error with the allowable limit on total 
system timing error of ±20 ms to determine a limit £max on allowable MET drift prediction error? If all the error 
sources are uncorrelated, we could combine all these sources using the common RSS technique which, using only 
the six highest data rates (because q(Asc) at the two lowest rates exceeds So = 20 ms), would give £max - 18.7 ms. 
However, since we did not know the statistical distributions of all the component terms, it was not clear when 
planning the NEAR timekeeping system if that would be a valid approach. Instead, we chose to take a more con- 
servative direction and used a straight summation of the component terms. We also chose to use only the four 
highest data rates, so the variation in C/TP to transmitter time synchronization is limited to the range ±0.13 to 
±0.79 ms. (This also has the effect of providing the bound U {) < 2 ms, as can be seen in Table 111.) This leads to 
an upper bound on composite system error, exclusive of the prediction of MET drift, of ±9.0 ms, and the bound on 
allowable MET drift prediction error becomes £ MA x = ±1 1-0 ms. 

As stated previously, if |£ D | < £max< the system accuracy requirement So = 20 ms is believed to be satisfied. How- 
ever, in deciding whether or not to add a new time coefficients triplet to the SCLK kernel, we must consider as 
well whether or not we expect |£d| < £max to remain true until the next opportunity to examine telemetry from the 
spacecraft. Therefore, the Mission Operations Center adds a new triplet to the kernel whenever |£ D | > £max - 
where the margin Mj is a somewhat arbitrary value chosen to allow for possible increase in |£ D | until the next ex- 
amination of telemetry 1 or 2 days later. As noted, the MET clock drift per day has been observed to vary by more 
than S () = 20 ms over the entire mission, so the selection of Mj is made with the assumption that the drift will not 
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change much over 1 or 2 days. If the temperature environment of the oscillator, a temperature compensated crys- 
tal oscillator (TXCO), remains fairly stable, then it is likely the drift in MET relative to TDT will not vary greatly. 
M r also accounts for the +/-0.5 ms uncertainty due to rounding the value of TDT to 1 ms in the SCLK kernel. The 
implementation of the Mission Operations Center portion of the NEAR timekeeping system actually uses A/ T = 6 
ms, so the decision is made to add a new time coefficients triplet to the SCLK. kernel whenever 


|£bl > ^max - Mj - 1 1 - 6 ms = 5 ms. ( 13 ) 

Our operational experience with this threshold value has been very satisfactory, resulting in less than one addi- 
tional SCLK time coefficients triplet per week on average. Of course, whenever a new' triplet is added, the ex- 
tended SCLK kernel must be distributed to the user community; thus, fewer changes to the kernel mean a lower 
incidence of logistical problems in performing such distributions. 

One question not answered by the time triplets in the SCLK kernel is whether or not |£ D | < £ MAX when a triplet 
was added, so the scientific community has no way of knowing how r probable it is that the svstem accuracy re- 
quirement was satisfied at that point in NEAR system time. In retrospect, it would have been useful to create an 
additional product (distributed on the World Wide Web through [20], where the NEAR SCLK kernel is also avail- 
able) which does provide that information. Alternatively, an extended form of the SCLK kernel could include that 
information, but that is not available in the current implementation. 


G. A I tentative Per spec ti ves on NEA R A ccuracy 

We can define a NEAR “extended clock” consisting of the SCLK kernel, the spacecraft MET counter, and the 
spacecraft oscillator that drives the MET counter. This is a generalization of the spacecraft clock, which consists 
of the MET counter and the spacecraft oscillator that drives the counter. We can then talk about the accuracy 
A {) < So of the extended clock and the clock error E c — TDT predicted - TDT AC tual, which must satisfy |£ c | < A () in 
order that the system accuracy 5 0 be satisfied. We do not know TDT actual , the actual time of the 1-PPS reference 
edge, w'hen we receive a new downlink telemetry frame containing a new value of MET but can only estimate it 
with TDT perce ,ved computed from equation (7). We can therefore only estimate E c by the perceived error £ P in 
the prediction of TDT provided by equation (12), where £ P = £ c ± U 0 , because TDT perce ,ved = TDT actual ± U 0 . 
We then require that |£ P | < Ao - £ 0 to ensure |£c| < A$. Since we require |£ P j < £max> we might assume £ MAX = 

A () - £ () , but that is not obvious. However, a look at the NEAR system time error budget does support this rela- 
tionship. Then A () — £max + Uo 1 1 + 2 ms = 13 ms. This tells us that the extended clock which includes the 
SCLK kernel can predict the TDT or UTC time of the NEAR 1-PPS reference edge to within 13 ms. The 
value /o - So — Aq ~ 7 ms is the portion of the system error budget allocated to error sources external to the ex- 
tended clock, as detailed in the system time error budget given earlier. Note that I 0 accounts for all uncertainties in 
distribution of time from the C/TP to the Imager and to the G&C system. 

We might ask if So can be chosen smaller for future missions using an open-loop timekeeping system similar to 
that used on NEAR. The error component 7 0 depends on the instrument suite and cannot be readily influenced by 
design of the extended clock. However, the extended clock accuracy Ay, can be improved (i.e., error can be re- 
duced) by appropriate spacecraft clock design, including selection of the oscillator. The minimum value ofAo 
depends on Uq and also depends on a trade-off between the interval between updates of the SCLK kernel and the 
uncertainty in the spacecraft clock drift rate. Suppose the interval between SCLK kernel updates is Af 0L and sup- 
pose that must be no less than some minimum value A/mjn» perhaps due to a limitation on the frequency of ground 
contacts. Suppose also that the uncertainty in our prediction of the drift rate of the spacecraft MET counter w ith 
respect to the standard time system (such as TDT or UTC) is 5 R. Whenever a new time coefficients triplet is 
added to the SCLK kernel, the new' estimate TDT, of the TDT of the 1-PPS reference edge may be in error by as 
much as £update = Uq, the uncertainty in the computation of TDT by equation (7). The clock drift rate, rate,, from 
the SCLK kernel may be in error by as much as 5 R, so the error of the extended clock is bounded by £ c = 
(A/ ol )(5£) ± Update = (A/ 0 l)(S£) ± U 0 . The perceived error in the extended clock is £ P = £ c ± £ 0 = (A/ 0 l)(S£) ± 
2L(). The decision threshold, as used above, is Ao - (Jq — Mj > |£ P | = |(A?ol)( 8£) ± 2Lo|. Using the maximum 
value of |£ P j, 
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(14) 


Ao > (Atoi_)(8R) + 3(7q+ Mj > (A^min)(5/J) + 3U n + Mj 

is the lower bound on the accuracy Ao of the extended clock, that is, of the prediction of the time of the onboard 
reference event with respect to the standard lime system. Note, however, that M T S (A/ M | N )(8^) + Q, where Q is 
the additional uncertainty due to the precision of TDT in the SCLK kernel, so 

Ao > 2(A/ M in)( 5^) + 3£/o + Q. (15) 

Equation (15) is particularly interesting because it reveals the explicit dependence of the minimum value ofA 0 on 
Af MIN , 8R, and U 0 . While A/ m ,n is probably determined by mission constraints, U 0 depends on design of the 
C&DH and downlink telemetry systems and 5 R depends on the oscillator used, the temperature regime to which 
the oscillator will be exposed and the amount of variation in oscillator frequency due to such design issues as 
power system regulation. There is also a dependence of 8R on Uo when the predicted clock drift rate is determined 
using an estimate of past drift. 

We can do even better than equation ( 15) if the SCLK kernel is updated with every ground contact instead of when 
a telemetry-based decision rule is satisfied, but that may present a logistics challenge in handling more frequent 
distribution of larger SCLK kernels. The decision rule method selected for NEAR allowed us to limit both the size 
of the kernels and the frequency of the distribution of time kernels to the user community while satisfying the 
bound on system timing error. Other approaches are available, as well, to provide much better accuracy of the 
extended clock. Use of reconstructed spacecraft ephemerides (to minimize the uncertainty in OWLT) and use of 
interpolation (to reduce the effect of 5R) are two techniques that can improve the accuracy of the clock. The 
MESSENGER mission, for example, is currently planning to use both interpolation and reconstructed ephemerides 
to achieve a spacecraft system time accuracy of +/- 1 ms. 

One last issue that often causes confusion in planning a timekeeping system is whether or not to use statistical 
methods. While NEAR used the simple relationship S 0 = I 0 + A 0 , if we have sufficient knowledge of the statistics 
of the error sources it may be appropriate to instead use a lower value for So computed with the RSS method. Use 
of the RSS method requires ( 1 ) that the error sources be uncorrelated and (2) that each component of the end-to- 
end system time error budget be expressed in exactly the same statistical terms. Suppose, for example, that we 
require an end-to-end system accuracy S 0 = 10 ms 3a, in the Gaussian sense, meaning that we require time at the 
instruments to be known 99.87% of the time to within S 0 = 10 ms of UTC. For clarity, we might write S 3o = 10 ms 
as the system accuracy requirement. We must then express lo and Ao in equivalent terms. It the components of the 
(instrument) error sources comprising /<> are all Gaussian, then / 3o is unambiguous. However, the components of 
Aq are generally not Gaussian and we may not even know the statistical nature of those parameters. If we do know 
the 3a extended clock accuracy A ia , then S 3o = [(/j^+UUa) 2 ]'" is the end-to-end system accuracy possible. 


IV. THE STEREO TIMEKEEPING SYSTEM 

The STEREO Mission includes two spacecraft scheduled to be launched in 2005. These spacecraft will provide 
measurements and images of coronal mass ejections (CMEs)' with particular emphasis on studying CMEs that 
affect the Earth. They will be in heliocentric orbits, one leading the Earth and slightly closer to the Sun and the 
other lagging the Earth and slightly farther from the Sun. 

The STEREO timekeeping system will include a space segment consisting of the two spacecraft and a ground seg- 
ment. The ground segment will be a component of the STEREO Mission Operations C enter at JHU/APL, which 
will communicate with the elements of the space segment via NASA s DSN. The two spacecraft in the space 
segment will operate independently of each other and will not communicate with one another. 

Some of the images taken by the two STEREO spacecraft will be combined during post-processing into stereo 
images of CMEs. It will be necessary to correlate the times of the images taken by the two spacecraft to within +1 
s. To accomplish this, the time of each image will need to be known to within ±0.5 s of a standard time system. 


’ As explained in [21], CMEs are distinct from solar flares and generally do not occur in conjunction with flares. 
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UTC has been chosen as that time system for convenience, particularly since one mission requirement is that the 
spacecraft bus provides an estimate of UTC to the instruments. In order to meet mission requirements in a way 
compatible with the system timekeeping error budget, a spacecraft clock accuracy of ±0.35 s of UTC is being 
used. 

The STEREO timekeeping system must support a primary mission of 2 years and a possible extended mission of 5 
years. The significance of these requirements will be clear when we discuss the effect of oscillator aging. 

A. The STEREO System Clock 

The STEREO spacecraft system clock must be accurate to within A 0 = 0.35 s of UTC. Mission design constraints 
establish the time reference event as the reference edge of a 1-PPS signal derived from the RF downlink oscillator. 
This is again called the C&DE1 reference edge (Fig. 1 ). The clock will be maintained to establish knowledge of 
the time of the C&DH reference edge to within ±0.35 s of UTC. Note that the 1-PPS signal is free-running and, 
unlike some spacecraft timekeeping systems [22], is never adjusted to meet the accuracy requirement. Rather, it is 
only know ledge of the time of the C&DH 1 -PPS reference edge that is maintained to within ±0.35 s of UTC. This 
estimate of the UTC of the reference edge is called the spacecraft UTC clock. 

Owing to mission design constraints, the STEREO timekeeping system will use a 32-bit unsigned integer MET 
counter with resolution of 1 s, which is incremented once per second by the 1-PPS pulse. The counter value drifts 
with respect to Earth time, because the 1 -PPS pulse does not occur at intervals of exactly 1 s. To provide a space- 
craft UTC clock that is accurate to within ±0.35 s of UTC, the MET value is mapped via a “UTC correlation regis- 
ter” (commonly called "UTCF” or “UT correction factor”) to the spacecraft UTC clock. The UTCF value is ad- 
justed by the STEREO Mission Operations Center using an uplink command when needed to maintain A 0 = 0.35. 
Consideration was given to having the onboard software automatically update the UTCF value based on expected 
clock drift, but that approach was rejected because ot the instrument teams’ desire to minimize the number of ad- 
justments to the UTC clock. Consideration was also given to scaling MET to reduce the effective clock drift rate 
and thereby extending the time between clock adjustments but that complication is not necessary for the clock 
performance needed for STEREO. Instead, the UTC clock value will be computed as MET + UTCF. 

B. Accuracy of the Spacecraft UTC Clock 

The UTC clock onboard each spacecraft provides an estimate UTC A pp RO ximate of the time of the C&DH reference 
edge. To maintain that estimate to within ±0.35 s of UTC, the STEREO Mission Operations Center will use 
downlinked telemetry to establish an estimate l TCpi fu ' e-ivi d of when the C&DH reference edge actually occurred. 
Combining that information with the expected clock drift, Mission Operations will schedule uplink commands to 
correct the C&DH UTCF register. This estimate will be computed using equation (4), which is repeated here: 

UTCperceived = UTCqrt - OWLT - TDsc ~ TFoffset- ( 16 ) 

Unlike NEAR, the STEREO downlink telemetry system is constrained to use telemetry frames not synchronized to 
the C&DH reference edge, so STEREO timekeeping is a Category 2 system. This means that the time of transmis- 
sion of each downlink telemetry frame could occur at any time within a 1-s window. That, in turn, means the un- 
certainty in TF offset must be at least 0.5 s, so the uncertainty ±U„ in UTCperceived is U u > S u = 0.5 s >Ao = 0.35 s, 
and therefore the requirement to maintain the spacecraft UTC clock to within A (l = 0.35 s of UTC cannot be satis- 
fied. Such an approach was mentioned earlier as the “unaided” Method 1 for Category 2 systems. 

This issue is resolved on STEREO by effectively extending the MET counter with an 8-bit vernier counter main- 
tained on the downlink RF card and incremented at a rate very close to 256 Hz, derived from the 1-PPS signal. 

This is the “vernier-aided” Method 2 for Category 2 systems. The vernier counter is reset to zero with each 1-PPS 
signal. Both the MET value and the 8-bit vernier counter value are “jammed” into the downlink telemetry frame 
secondary header just before the telemetry frame is encoded and transmitted. This reduces the uncertainty in 
TFoffset to about 4 ms in the worst case or 2 ms in the best case. Only the 32-bit integer value is used in the map- 
ping from MET to spacecraft UTC. 
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The uncertainty in OWLT (the one-way light time) is determined primarily by the uncertainty in knowledge of the 
spacecraft ephemeris. STEREO ephemeris will be known to within ±7500 km in all directions, an upper bound set 
by image resolution requirements. This translates to ±25 ms uncertainty in OWLT. The standard DSN service 
provided to NEAR by the DSN gives UTC grt to within ±0. 1 ms, and it can be assumed that the same degree of 
service will be available for STEREO. The uncertainty in TD SC is also expected to be very small. With these val- 
ues, an upper bound for the uncertainty in UTCperceived is A) ~ 30 ms. It is likely that the requirement on space- 
craft ephemeris will be refined to a much lower value resulting in a lower Uq but 30 ms is the level being used in 
the current planning phase. 

C. Spacecraft UTC Clock Drift 

The spacecraft UTC clock drifts because the 1-PPS signal does not occur at intervals of exactly 1 s; that, in turn, 
occurs because the RF downlink oscillator frequency differs from its nominal output frequency of 30.6 MHz. The 
specifications for the High Stability Oscillator (HSO) to be used on STEREO are 

• Nominal output frequency of 30.6 MHz 

• Initial setting accuracy of ±5 x 10 * 

• Aging rate of< 5 x 10 1(1 per 24 hours 

• Frequency as a function of temperature of 1 x 10' n /°C over the oscillator operating range of- -5° to +25°C 

The time A/ M in microseconds gained or lost by a clock driven by this oscillator is given approximately by the 
equation (from Reference [23]): 


A/ m = 8.64[(A flf)t + (kl2)f], ( 1 7) 

where 

A/7/is the oscillator reference offset (setting offset) in parts in 10~ H) ; 
k is the oscillator aging or drift rate in parts in 10" 5O /day; and 
t is the elapsed time in days. 

Using equation ( 17), the spacecraft UTC clock drift rate works out to 

• 4.3 ms/day at the start of the mission 

• 35.9 ms/day worst case after 2 years 

• 83.2 ms/day worst case after 5 years 

Variation in temperature is expected to be the major contributor to the uncertainty of clock drift. The uncertainty 
of clock drift due to temperature variations is (1 x 10 n /°C) x 30°C = 0.33 x 10 = 0.026 ms/day. 

D. Clock Correction Interval 

The STEREO Mission Operations Center will uplink a command to adjust the UTCF value in order to correct the 
spacecraft UTC clock whenever necessary to guarantee that the clock remains accurate to within A 0 = 0.35 s of 
UTC. It is important to understand what the interval (Ar CL ) between adjustments would be in the worst case. 

There are three factors to consider: (1) uplink clock correction insertion error £)ns> (2) false error due to overesti- 
mate of clock error estimator, and (3) spacecraft clock drift. 

1) Clock insertion error 

Equation (4) introduced UTCperceived, the estimate on Earth of the UTC corresponding to the C&DH reference 
edge. We can express this estimate as UTCperceived ~ UTC(USNO) ± U o, so a clock correction effective at time h 
based on UTCperceived determined for time /, could be in error by U {) plus some uncorrected clock drift for the 
interval U — t\. In the worst case, the clock correction insertion error is £)ns = Uo + An s = A) + c)(h ~ U), where 
Ru is the worst-case uncertainty in clock drift rate and Dins is the uncertainty in clock drift for the interval U - t\. 

If clock correction uplink commands are scheduled a week in advance, then in the worst case, the uncorrected 
clock error due to possible temperature variations would be Ans ~ 0.026 ms/day x 7 days ~ 0.2 ms. The aging 
effect over 7 days would be ~ 0.3 ms and Ru would need to account for that. Ru also depends on how well we 
predict the rate of clock drift and that in turn depends on the specific method used for the prediction. 
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2) False error due to overestimate in E P 

The error in the spacecraft UTC clock value UTC approximate is E c ~ UTC A pp RO ximate - UTC(USNO), where 
UTC(USNO) is the actual but unknown time of the C&DH reference edge identified by UTC approximate- At the 
Mission Operations Center, the time of the C&DH reference edge is estimated as UTC PERC eived, so the perceived 
error in the spacecraft UTC clock is £ P = UTC APPRO ximate - UTC PERC eived = UTC APPRO ximate - UTC(USNO) ± Uq 
- £ t ± £ 0 . As long as |£ P ; < A 0 - Uq , we know |£ c | < Aq - 0.35 s, so the clock accuracy requirement is satisfied. 

Suppose now that A 0 - Uq < |£ P | < A 0 ■+■ U 0 . Since the criterion |£ P | < A 0 - U 0 is not satisfied, we might conclude 
that [£c| > A 0 even if |£c| < Ao. The maximum actual clock error that can be tolerated using the decision rule |£ P | < 
A o ~ Uo without falsely concluding that the spacecraft clock is less accurate than A 0 relative to UTC is 
i^l < °l^er words, if |£ c | < Aq — 2U 0 is satisfied, then |£ P | < A o — Uo will always be satisfied, and the 

Mission Operations Center will conclude that the clock error satisfies the accuracy requirement |£ E -J < Aq — 0.35 s. 

3) Effect of clock drift on the interval between clock corrections 

The MET counter value (and the UTC clock value to which MET is mapped) drifts with respect to Earth time be- 
cause the 1-PPS pulse does not occur at intervals of exactly 1 s. Suppose R{t) is the clock drift rate and varies with 
time, and £ w c ^ \R(t)\ is the worst-case clock drift for some time interval of interest. Suppose also that A/ C l is the 
worst-case allowable interval between clock corrections. The worst-case spacecraft UTC clock error is then j£ c | = 
£ins + tfwc x A/a.. In the previous section we determined that |£ G j < Aq - 2Uq is necessary to ensure the decision 
rule E P j < A {) - U 0 is satisfied. That provides the result 


A/cl < (Aq - 2Uq ~ £ IN $)/£wc • (18) 

Using Aq = 0.35 s, U 0 = 30 ms, and D IN s - 10 ms, with the clock drift rates £ wc computed from equation ( 1 7), the 
maximum allowable interval between clock corrections is 

• > 1 month at the start of the mission 

• - 7 days after 2 years 

• - 3 days after 5 years 


V. TIMEKEEPING SYSTEM DESIGN TRADE-OFFS AND GUIDELINES 


Equation (4), repeated as equation (19), provides insight into the design of Category 1 and Category 2 timekeeping 
systems: 


UTC PER ceived ~ UTC grt - OWLT - TD SC - TF 0 ffset • (19) 

The uncertainty in UTCgrt is determined by the DSN or other ground receiving system employed and is not gen- 
erally a mission parameter that can be controlled. When DSN is used, a bound of ±0.1 ms on the uncertainty can 
be provided. 

The uncertainty in OWLT depends on the uncertainty in our knowledge of the spacecraft ephemeris. For NEAR, 
the best available ephemeris information can in theory provide a level of OWLT uncertainty of ±1 ms. However, 
the ephemeris information is sometimes not that good. For STEREO, the science imaging requirements impose an 
ephemeris accuracy of no worse than ±7500 km, equivalent to 25 ms in OWLT uncertainty. Actual STEREO 
ephemeris accuracy may be much better than this, perhaps even at the level of ±200 km or < 1 ms in OWLT uncer- 
tainty. The NASA-sponsored Deep Space Systems Technology (DSST or X2000) program at JPL aims at deter- 
mining OWLT to within ±30 ns ( 10-m range uncertainty). Earth-orbiting satellites would be expected to have 
OWLT of only a few milliseconds and uncertainty in OWLT of « 1 ms. 

The uncertainty Use in TD SC + TFqffset is directly affected by the design of the C&DH and downlink telemetry 
systems. Let j £> r S c be the value of U S c for a Category 1 timekeeping system and 2 £ sc the value of C S( for a Cate- 
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gory 2 system. For a specific mission with given uncertainty of OWLT, the observability U 0 of the spacecraft 
clock relative to a standard time system depends on f sc- so we would like to choose a timekeeping system cate- 
gory based on which of , U sc or 2 (/ S c can be made smaller. However, other spacecraft design considerations may 
dominate. Downlink telemetry rates, especially for interplanetary missions, are constrained by a number of issues 
independent of timekeeping, and it may be difficult to choose downlink telemetry frame sizes to enable synchroni- 
zation at those rates to the C&DH reference edge. The “streaming” downlink telemetry used with Category 2 sys- 
tems decouples the downlink rates and frame sizes, and such systems must provide some method (such as the 
STEREO vernier-aided method) for establishing accurate knowledge of the time of the C&DH reference edge, 
which is typically the reference event to which the time of all other events on the spacecraft can be referred. 

The choice between an open-loop timekeeping system in which the spacecraft clock is free-running and never cor- 
rected by ground control and a closed-loop system in which the spacecraft clock is controlled and corrected by 
ground command is not always obvious. This issue was extensively debated for STEREO, which must compare 
data from two spacecraft, and a closed-loop system was the method adopted. From a Mission Operations Center 
perspective, use of a free-running spacecraft clock requires not only that correlation of the clock to UTC or some 
other standard time system be established on the ground but that clock correlation and prediction information tor 
each spacecraft be disseminated and made available promptly to the user community. This dissemination may 
involve a considerable logistics effort. For such a system, the observability U u of the clock and stability of clock 
drift are important. Clock correlation and prediction information can be updated whenever necessary, provided 
that the clock drift is such that the frequency of updates is low enough to be logistically feasible and high enough 
that the behavior of the clock is known to sufficient accuracy between updates. For a closed-loop system, the 
maximum allowable interval Af CL between clock corrections is a critical parameter, as is the effective clock drift 
rate. These parameters must ensure that control of the spacecraft clock by the Mission Operations Center is practi- 
cable, and they are dependent on required clock accuracy A„, clock observability U 0 , and clock drift characteristics. 

A major advantage of open-loop timekeeping versus closed-loop is that timekeeping errors in an open-loop system 
can be corrected after the fact, whereas a closed-loop timekeeping system that has already time-tagged spacecraft 
and instrument data with inaccurate times cannot easily correct that error. 

It is informative to compare open-loop system accuracy with closed-loop system accuracy. Given the same in- 
strument suite with time error budget /o, the end-to-end system accuracy So depends on the clock accuracy Aq. The 
accuracy of the extended clock of a NEAR-type open-loop system is given by equation ( 1 5), which is repeated 
here: 


Aoi = A 0 > 2(A/ M in)( 5«) + 3 Do + Q , (20) 

and the accuracy of the spacecraft clock of a STEREO-type closed-loop system, rewriting equation (18) and using 
the worst-case relationship £)ns = D , o + Dins, is 


^cl - Ao > (A/clK-Rwc) + 3Do + Ans • (2 i ) 

The most notable difference between these two equations is the dependence ofAoL on the uncertainty 6R of space- 
craft clock drift rate versus the dependence of A C l on the worst-case spacecraft clock drift rate R wc . Note that U 0 
is the same in both equations and applies to both Category 1 and Category 2 timekeeping systems. 

The dependence of A„ on 3U„ in (20) and (2 1 ) is due to the use of a telemetry-based decision rule to determine 
when to adjust the spacecraft clock component of a closed-loop system or to adjust the extended clock SCLK ker- 
nel (or equivalent) of an open-loop system. The decision rule bounds the error E P perceived from downlink te- 
lemetry to \E r \ < A,, - Uo to ensure the actual clock error is bounded by \E C \ < A„ . When the interval between 
clock adjustments is instead determined by some a priori rule, such as once per ground contact or once per w eek, 
the dependence of A» becomes U„ . However, telemetry could then confirm the accuracy of the clock only to the 
level A„ + 2U U because E c cannot be observed directly. For some applications, it may be appropriate to define a 
slightly larger A„ which depends on 3U„ and which can be directly verified through downlink telemetry. 

Techniques are available to provide better accuracy than available with the NEAR-type design (equation 20) or 
w ith the STEREO-type design (equation 21). It was mentioned in the discussion of the NEAR extended clock that 
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several methods could provide better accuracy for open-loop systems. Closed-loop systems, as well, can be de- 
signed to be more accurate through several approaches. If the mapping from MET to the onboard estimate of UTC 
includes a scaling factor to account for the drift of MET relative to UTC(USNO), the clock drift rate in equation 
21 is replaced by the “error” or uncertainty 5R in prediction of the drift rate of the spacecraft MET counter. Note 
that 6R must account for any oscillator frequency variation due to temperature or voltage changes or any other 
environmental effects. Combining scaling with periodic clock adjustments gives 

^cl = > (At C i)(dR) + U {) + D )NS . (22) 


One important issue that should not be overlooked in design of a space mission timekeeping system is the question 
of how to test the performance of the system. Since the ground segment of the NEAR timekeeping system was 
automated only after launch, it has not been possible to perform a “ground truth" verification of the performance 
of the end-to-end NEAR timekeeping system. Measurements taken by the NEAR X-Ray/Gamma-Ray Spectrome- 
ter have been independently verified to be accurate to within 100 ms of UTC, but the mission goal of system end- 
to-end accuracy of S 0 = 20 ms has never been verified. (Note, however, that the performance of the NEAR Shoe- 
maker timekeeping system has been completely satisfactory; see [24], for example.) Since STEREO is planned 
for a future launch, the opportunity exists to perform “ground truth” verification both on the ground and during the 
month or so after launch, when the spacecraft are flying essentially the same trajectory toward the moon and be- 
fore they separate into heliocentric orbits leading and lagging the Earth. 


VI. FUTURE DIRECTIONS: FORMATIONS 


With current interest in collections of interplanetary spacecraft flying in formation [25] and in constellations about 
planetary bodies [26], the extension of the ideas presented in this paper to such applications is of interest. In gen- 
eral, we will want to know the relative biases between the clock on one spacecraft and the clocks on the other 
spacecraft in a formation or constellation of space vehicles. We are concerned here with spacecraft that communi- 
cate directly with each other. 

We can easily generalize equation (4) to the transfer of telemetry between two spacecraft. Suppose spacecraft A 
sends to spacecraft B the value |Ca of its clock at time t\ and spacecraft B responds by sending to spacecraft A the 

value :C B of its clock at time / 2 as well as the clock time |C B rt at which spacecraft B received the transmission 

from spacecraft A and the offset value TF$ca the telemetry frame spacecraft B received from spacecraft A. It 
follows directly from equation (4) that 

|£\b = iCa - jC B rt +■ OWLTab + TDsca + TFsca (23) 

2^ba ~ 2 C B - jCart + OWLTba + TDscb + TF scb , (24) 

where 

\E\q is an estimate of the bias ]Ca — i C B of the clock on spacecraft A relative to spacecraft B; 

2 £ ba is an estimate of the bias 2 C B - 2 C A of the clock on spacecraft B relative to spacecraft A; 
iC/ is the time of the clock on spacecraft j (= A or B) at time 

i^brt is the time of the clock on spacecraft B representing the time of receipt of the transmission from 
spacecraft A; 

2 C A R T is the time of the clock on spacecraft A representing the time of receipt of the transmission from 
spacecraft B; 

OWLT,, is the one-way light time (signal transit time) from spacecraft / to spacecraft j; 

TDso is the telemetry transmission delay through spacecraft /; and 

TFstv is the time offset of a telemetry frame relative to the C&DH reference edge of spacecraft L 

If the total transaction time A/j = 2 C A rj — ]C A for the two-way communication is small, perhaps a few r seconds, 
then the change in bias between the two spacecraft clocks will be very small. As an extreme example, suppose the 
two clocks are drifting rapidly with respect to each other at the rate of about 100 ms/day; then, the change in clock 
bias 5 B ias = 2 ^ab - i^ab over a few r seconds would be a few^ microseconds. The approximation 5 B[as = 0 will be a 
good estimate for some missions. 
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Let 8 0 wlt = OWLTba - OWLTab- If the radial distance between the two spacecraft is changing slowly, then, for 
many applications, for a sufficiently small two-way transaction time Af T , we can assume 8 0 wlt ~ 0- Defining 8 
= 8 bias + 8owlt , v = TD sca - TDscbi and 4> = TF SCA - TFscb and solving equations (23) and (24), 

i£ab = ‘A[(|C a - |C BRT ) - (jCb - 2 f art) + <j) + v - 8] 

~ '/ 2 [(iCa — 1 f brt) ~ (zCb — tCart) + <t> + v ], for 8 ~ 0. (25) 

This offers a simple approach to estimating the biases between spacecraft clocks for a collection ot spacecraft fly- 
ing in formation, without explicit knowledge of the range between spacecraft, and allows meaningful definition ot 
a "formation time” or “constellation time” [27] suitable for time-tagging events observed by any of the spacecraft 
in the formation. Solving equations (23) and (24) for OWLT can also provide a coarse estimate of range between 
spacecraft. 

Remembering the earlier statement that "The primary goal of spacecraft timekeeping is to establish knowledge of 
the time of an onboard reference event with respect to which the time of every other event on the spacecraft can be 
measured,'' we should ask to what reference event is the above "formation time" measured? The answer is not 
straightforward, and may be one of several possible answers. A simple approach is to set the formation time equal 
to the clock time of one of the spacecraft, implicitly defining the "reference event" as the C&DH reference edge 
for that particular spacecraft. That leaves unanswered the engineering question of what to do when the clock of 
that particular spacecraft fails. Another approach, similar to [27], is to define the formation time as an "ensemble 
time" that somehow r combines the values of the clocks of all the spacecraft. How to define such an ensemble time 
and how (or whether) to relate that to a "reference event" may be a fruitful area for future study. Such an ensem- 
ble approach does provide a more robust and reliable system for defining formation time than depending on the 
health of a particular spacecraft clock. 


VII. SUMMARY 

This paper introduced the concept of Category 1 and Category 2 spacecraft timekeeping systems and discussed the 
dichotomy between such systems in terms of the relationship between spacecraft clock resolution and accuracy. 
The similarities between the tw o categories were discussed, and equation (4) for estimating the time of the on- 
board reference event was applied to both. Distinctions between open-loop systems and closed-loop systems were 
examined and the various factors that influence the accuracy of such systems were discussed. Trade-offs and 
guidelines for designing spacecraft timekeeping systems were suggested, and the importance of “ground truth" 
verification noted. Finally, a possible extension of these ideas to spacecraft flying in formation was introduced. 

Successful application of these principles to the NEAR Shoemaker timekeeping system was described, as was the 
proposed implementation of the STEREO timekeeping system. 


4 For example, for Deep Space 3 (DS3) [25], spacecraft separations will be no more than I km, so we would expect 6 0 wlt < 1 For the Mars 
constellation described in [26], spacecraft separations would be - 3000 km, so we would expect Sown « Inis. 
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